Skip to content

docs: harmonize governance and contribution authority - #5

Open
logbie wants to merge 3 commits into
devfrom
docs/sawako-log-19-governance
Open

logbie wants to merge 3 commits into
devfrom
docs/sawako-log-19-governance

Conversation

@logbie

@logbie logbie commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Align contribution governance with Brad's approved LOG-10 policy and dev/CEO delegations, tracked by Paperclip LOG-19. Feature branches target dev; Yomi reviews the current revision and exact-commit CI remains required.

Changes

  • Add identical versioned common contribution policy and reconcile contributor, agent, testing, security and AI guidance.
  • Add the PR evidence checklist; preserve project-specific technical and Apache-2.0 guidance.
  • Add Scribe governance, contributor, security, testing and agent entry points.

Compatibility and risk

Documentation change is R0. No language/runtime, palette, licensing or product behavior changes in this documentation commit.
This PR is stacked on unmerged CI PR 4, and targets dev. Review the documentation commit separately from that dependency; the full base diff still includes its independently reviewed CI work. Do not merge either past its review/control gates.

Independent GitHub approval identity is deferred: shared logbie cannot approve its own PR. Yomi review and protected-branch requirements remain binding. No bypass.

Validation

Documentation commit: b328ddeecd214b5c47015cca27c1e4bc0e71dc47.
Behavior tests N/A — the new commit edits prose and PR guidance only; required Actions are not waived.
Local git diff --check, changed-Markdown local-path checks and common-policy equality checks passed. Documented shell entry points passed bash -n.
External URLs and heading anchors were not network-validated. Actions on this new SHA are pending; no old-head pass is claimed.

Checklist

  • Owned documentation branch targets dev; no direct protected-branch push.
  • Scope, local checks, documentation-only exception and dependency are explicit.
  • No new credential, workflow, runtime or production changes in the documentation commit.
  • Current-SHA required Actions all passed; skipped/unrun checks explicitly recorded.
  • Yomi reviewed this revision and all triggered bot feedback is dispositioned.
  • Immediately-before-merge checks/reviews and independent approval controls satisfied.

The owner tracks pending Actions/bot feedback on Paperclip LOG-19 with a scheduled monitor. Main/release/tag/deploy decisions follow GOVERNANCE.md; this PR grants no merge permission.


Devin Review

Co-Authored-By: Paperclip <noreply@paperclip.ing>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: cd03ce67-848b-4550-9ff7-83562fe92e6b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 potential issues.

Devin Review

Comment thread .github/workflows/ci.yml
Comment on lines +3 to +5
on:
pull_request:
branches: [main, dev]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Merged commits lack release checks

When promotion creates a new main commit, pull_request never checks that SHA. The release gate requires exact-commit results, so releases and deployments remain blocked.

Learn more

The workflow runs for pull requests targeting main and dev, but not for commits created when those PRs merge. A merge or squash creates a new SHA that was never the checked-out commit in the PR run. The promotion gate requires passing checks on the exact commit being released or deployed. Even a green promotion PR therefore cannot supply checks for the resulting main commit.

Example: A promotion PR passes both jobs, then merges as commit abc123 on main. Neither job runs on abc123; the PR's green jobs belong to its pre-merge run, so Azusa cannot release abc123 under the documented gate.

Recommended fix: Add a push trigger for protected branch commits, at least main, and verify that the required check contexts run and pass for the resulting commit before releases or deployments. Keep the PR checks for pre-merge validation.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread .github/workflows/ci.yml
Comment on lines +24 to +35
- name: Check changed Markdown whitespace and required documentation
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
run: |
git diff --check "$BASE_SHA" HEAD -- '*.md'
test -s README.md
test -s docs/SYNTAX.md
test -s docs/DESIGN.md
- name: Check documented shell entry points
run: |
bash -n tests/run.sh
bash -n examples/run.sh

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Documentation CI does not cover the R0 evidence

Documentation checks validates whitespace, file presence, and shell syntax, but not links or policy consistency. The R0 testing policy calls for relevant link and policy checks; record those separately before treating prose changes as verified.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants